Threat Level: green Handler on Duty: Richard Porter

SANS ISC: HTTP Header Usage Statistics HTTP Header Usage Statistics


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

This is a continuation of work started by Brough Davis as part of his software security project for his Masters in Information Security Engineering. The main goal of this project is to find how many sites use security relevant headers, like for example the X-XSS-Protection or X-Frame-Options headers.

Below you will find a table/histogram showing how many times we found each header (security relevant or not). We access the index page of each site using a "head" request. The list of sites is derived from Alexa's Top 1 Million sites. We try to poll as many sites as possible each day.

As we collect more data, we will plot changes over time.



All Headers Active In The Past Month
Header Popularity
Set-Cookie
Content-Type
Date
Connection
Server
Cache-Control
Vary
Expires
X-Frame-Options
Strict-Transport-Security
Content-Length
X-Content-Type-Options
Link
Last-Modified
Cf-Request-Id
CF-Cache-Status
CF-RAY
ETag
X-XSS-Protection
Accept-Ranges
Expect-CT
Pragma
X-Powered-By
X-Cache
Via
Age
Content-Security-Policy
Report-To
NEL
Alt-Svc
Referrer-Policy
Access-Control-Allow-Origin
Content-Language
X-Amz-Cf-Pop
X-Amz-Cf-Id
X-Cache-Hits
X-Served-By
X-UA-Compatible
P3P
X-Xss-Protection
X-Download-Options
X-Request-Id
X-Timer
Access-Control-Allow-Headers
Access-Control-Allow-Methods
X-Varnish
X-Adblock-Key
X-FRAME-OPTIONS
X-Permitted-Cross-Domain-Policies
Access-Control-Allow-Credentials
Content-Security-Policy-Report-Only
P3p
X-Runtime
X-AspNet-Version
Accept-CH
X-DNS-Prefetch-Control
X-Cache-Status
X-Ua-Compatible
X-Drupal-Cache
Accept-CH-Lifetime
X-Check
X-Generator
X-Cacheable
Server-Timing
X-Envoy-Upstream-Service-Time
Timing-Allow-Origin
X-Iinfo
X-Request-ID
X-Drupal-Dynamic-Cache
Access-Control-Expose-Headers
Feature-Policy
X-Content-Security-Policy
Content-Encoding
X-CDN
Status
Upgrade
X-AspNetMvc-Version
Access-Control-Max-Age
X-Via
X-Amz-Request-Id
CF-Ray
X-Amz-Id-2
Host-Header
Allow
X-Backend
Cf-Edge-Cache
X-Cache-Group
Request-Context
X-Robots-Tag
Keep-Alive
X-Server
X-Hacker
X-UA-Device
X-AH-Environment
X-Turbo-Charged-By
X-Ws-Request-Id
X-Proxy-Cache
X-Rq
X-Vhost
X-Age
Xkey
EagleId
X-Dispatcher
X-Server-Powered-By
X-Amz-Version-Id
X-Dns-Prefetch-Control
X-Varnish-Cache
Grace
Cf-Apo-Via
X-LiteSpeed-Cache
X-Page-Speed
X-Pingback
Cf-Railgun
X-Swift-CacheTime
X-Swift-SaveTime
X-Pantheon-Styx-Hostname
X-Styx-Req-Id
X-Device
EagleEye-TraceId
Ali-Swift-Global-Savetime
X-Aws-Lambda-Call-Status
X-CST
X-WebKit-CSP
X-Backend-Server
X-OneAgent-JS-Injection
Permissions-Policy
X-Server-Id
Accept-Ch-Lifetime
X-Readtime
X-Response-Time
X-Host
X-Akam-SW-Version
Request-Id
Surrogate-Control
X-EdgeConnect-MidMile-RTT
X-EdgeConnect-Origin-MEX-Latency
X-HW
X-Nginx-Upstream-Cache-Status
X-Cloud-Trace-Context
X-Nginx-Cache-Status
X-Node
X-Application-Context
X-Country-Code
X-Cache-Lookup
X-Litespeed-Cache
X-Oneagent-Js-Injection
X-Trace
Content-Location
X-Ruxit-JS-Agent
Service-Worker-Allowed
X-Url
X-Country
X-Content-Type
X-Clacks-Overhead
X-ECACHE
X-Edge
X-Origin-Cache-Key
Accept-Ch
X-Mcache
X-Mod-Pagespeed
Cross-Origin-Opener-Policy
X-Amz-Server-Side-Encryption
X-Midtier
X-Rack-Cache
Cache-Tag
X-FTR-Request-ID
X-MS-InvokeApp
Nginx-Cache
X-Upstream
X-ESI
X-Powered-By-Plesk
X-TtlSet
X-Vname
X-PC
Rating
Edge-Control
X-Browser-Type
X-D2id
X-Server-Name
X-Element-Page-Cache
Verso
X-Kinja
X-Kinja-Server
X-Kinja-Build
X-Kinja-Revision
X-GoogleNews-Bot
X-Exp-Id
X-Cdn-Fetch
X-Exp-Variant
X-Cnection
X-Times
X-Ruxit-Js-Agent
SPRequestDuration
SPIisLatency
X-Ac
X-B3-TraceId
AR-PoweredBy
AR-SID
AR-ATIME
AR-Request-ID
X-Abt-Application-Version
X-Vcap-Request-Id
X-Navigation-Version
SPRequestGuid
X-SharePointHealthScore
X-Dw-Request-Base-Id
X-NF-Request-ID
X-RateLimit-Remaining
X-GitHub-Request-Id
X-Ser
X-VARITI-CCR
AR-CACHE
Pinterest-Version
X-Pinterest-Rid
Pinterest-Generated-By
X-ASPNET-VERSION
S
X-Cache-Key
Pagespeed
X-Sol
Display
X-Middleton-Display
X-Mg-S
RTSS
Edge-Cache-Tag
X-Ttl
X-Client-IP
X-NWS-LOG-UUID
X-Cache-TTL
X-Amzn-Trace-Id
X-Amz-Rid
Fastly-Restarts
Origin-Trial
X-Powered-CMS
X-Goog-Hash
X-Kraken-Loop-Name
X-Instrumentation
X-Server-Lifecycle-Phase
X-Erf-Bev-Bev-Is-Generated
X-Erf-Bev-Bev
X-Server-ID
Cache-Status
X-Kinsta-Cache
X-Edge-Location-Klb
Access-Control-Request-Method
X-Version
X-Content-Security-Policy-Report-Only
X-Varnish-TTL
X-Recruiting
X-ARC
X-Webkit-Csp
X-TraceId
X-Content-Digest
Arr-Disable-Session-Affinity
X-Erf-Stays-Pdp-Viaduct-Migration-Web-V2
X-T
X-SRCache-Store-Status
X-Middleton-Response
X-SRCache-Fetch-Status
X-Forwarded-For
Response
X-MSEdge-Ref
X-Ua-Device
Content-MD5
MicrosoftSharePointTeamServices
X-Accel-Expires
TP-Cache
X-Shield-Request-Id
X-Cached
X-Hits
X-Id
X-RateLimit-Limit
X-Fastcgi-Cache
Public-Key-Pins
MS-Author-Via
X-Request-Received
X-Request-Processing-Time
Server-Node
X-Ua-Browser
Front-End-Https
Cross-Origin-Resource-Policy
X-HS-Hub-Id
X-HS-Combine-CSS
X-FTR-Backend-Server
X-Country-Code-Real
X-FTR-Balancer
X-FTR-Cache-Status
Payment
X-HS-Cache-Config
X-HS-Content-Id
X-FTR-Backend
X-FTR-Expires
X-Frontend
X-DIS-Request-ID
X-Forwarded-Proto
X-LLID
X-HP-Trace-Id
X-Jurisdiction
X-Daa-Tunnel
X-HP-Webp
X-GUploader-UploadID
TP-L2-Cache
Realpath
X-LB-Cache
Cache-Tags
X-Protected-By
X-Amz-Apigw-Id
X-Amzn-RequestId
X-Origin-Server
X-WebKit-CSP-Report-Only
X-Distributor
X-Microsite
X-Request-Handler-Origin-Region
Count-Hit
X-FastCGI-Cache
Mrf-Cache-Status
MRF-Tech
X-B3-TraceId-Primal
X-F-Cache
X-Activity-Id
X-AppVersion
X-Kinja-CCPA
X-Az
X-Page-Id
X-NGENIX-Cache
X-Www-Served-By
X-Cluster-Name
X-Hostname
X-Varnish-Backend
Referer-Policy
Accept-Charset
X-ORACLE-DMS-RID
X-App-Server
X-Geo-Country
X-Envoy-Decorator-Operation
X-Debug-Info
Host
Fastcgi-Cache
X-Varnish-Server
X-Correlation-Id
X-Kong-Upstream-Latency
X-PressLabs-Stats
X-Kong-Proxy-Latency
X-TTL
X-Goog-Metageneration
X-FB-Debug
Access-Control-Allow-Method
X-Rid
X-Git-Hash
X-Oracle-Dms-Ecid
Retry-After
X-RateLimit-Reset
X-XRDS-LOCATION
X-ORACLE-DMS-ECID
X-Content-Options
X-CSRF-Token
X-Load-Cache
Server-Name
X-Upgrade-Enabled
X-Px
X-Tt-Trace-Tag
X-Tt-Trace-Host
X-Contextid
DC
X-Grace
TCN
Charset
X-Revision
X-Signature
X-B-Cache
X-B
X-Trace-Id
X-Origin-Cache
Paypal-Debug-Id
X-Type
X-Ezoic-Cdn
X-Datadog-Parent-Id
X-Cache-Control
X-App-Environment
X-TT
X-B3-Sampled
X-Datadog-Sampling-Priority
X-Oracle-Dms-Rid
X-Datadog-Trace-Id
Cleartype
X-Amz-Meta-S3cmd-Attrs
X-Flags
X-Mobile
X-Providence-Cookie
X-Request-Guid
X-Aspnet-Duration-Ms
X-Route-Name
Section-Io-Cache
X-Is-Crawler
X-Seen-By
X-Ratelimit-Limit
X-Fb-Rlafr
X-Fastly-Request-ID
X-Amz-Replication-Status
Healthy
Frame-Options
X-Magnolia-Registration
X-Language
X-Whom
X-Logged-In
X-Fastly-Request-Id
X-Wix-Request-Id
X-Goog-Stored-Content-Length
X-Varnish-Ttl
X-Node-Name
X-Goog-Storage-Class
X-Goog-Stored-Content-Encoding
X-Goog-Generation
X-TEC-API-VERSION
X-TEC-API-ORIGIN
Filterid
X-TEC-API-ROOT
X-EdgeConnect-Cache-Status
X-Azure-Ref
X-Proxy
X-App-Version
X-N
X-Newrelic-App-Data
Content-Disposition
Backend
Akamai-GRN
X-Air-Pt
Upgrade-Insecure-Requests
Refresh
X-Template
NGB
X-Proxy-Cache-Info
X-Response-Served-From
X-Original-Request-Id
X-Tumblr-Pixel-0
VIX-Pulpo-Upstream-Status
VIX-Pulpo-Node
X-Tumblr-Pixel
X-RemovedCookies
X-Tumblr-User
X-ProcessESI
X-Unique-Id
X-Tumblr-Pixel-1
X-Rendered-As
X-Yottaa-Metrics
X-UUID
X-Yottaa-Optimizations
X-RTag
MS-CV
Ms-Operation-Id
X-Debug-IsPreview
X-Datadog-Sampled
Viewport
X-Debug-IsConnected
X-Is-Bot
X-Ratelimit-Remaining
X-Amzn-Remapped-Content-Length
X-IPS-LoggedIn
X-Instance
X-FW-Server
X-FW-Type
X-FW-Version
X-FW-Static
X-G
X-Debug
X-FW-Serve
SD-X-WS
X-Adobe-Content
X-Adobe-Loc
Liferay-Portal
X-FW-Dynamic
X-FW-Hash
X-Servername
X-Device-Type
X-Varnish-Grace
X-NYM-Debug-Backend
X-WP-CF-Super-Cache
X-Region
Fastly-SIE
X-WP-CF-Super-Cache-Cache-Control
Fastly-SWR
X-User-Agent
X-Cache-Grace
X-Cacheable-TTL
Url
From-Origin
X-Tec-Api-Version
X-Tec-Api-Root
X-Tec-Api-Origin
X-Page-View
X-Jobs
X-L-Path
Country
X-Rule
X-Environment-Context
X-Hl-Ver
X-Status
X-Cache-Hit
X-B3-SpanId
X-Backend-Name
Surrogate-Key
ServerID
X-Webkit-CSP
X-Air-Hostname
Countrycode
X-Air-Source
X-Air-Trace-Id
X-Cache-Age
X-VC-Cache
X-Time
X-Content-Powered-By
X-Hosted-By
X-Origin-CC
X-Origin-TTL
Alternate-Protocol
X-CCDN-CacheTTL
X-Hcs-Proxy-Type
X-CCDN-Origin-Time
X-Http-Reason
X-Cache-Status-Check
X-NODE
Amp-Access-Control-Allow-Source-Origin
X-INCAP-ABP
X-Akamai-Request-ID2
X-HTML-Minification-Powered-By
WPO-Cache-Status
WPO-Cache-Message
Protected
X-Via-JSL
Version
X-B3-Traceid
X-Akamai-Edgescape
X-Rocket-Nginx-Serving-Static
SRV
X-CDN-Forward
X-Nginx-Cache
GEO-INFO
X-Storage
X-Framework
CF-IPCountry
X-Accel-Version
X-Source
X-Edge-Location
Access-Control-Request-Headers
X-Cache-Rule
X-XRDS-Location
X-WP-CF-Super-Cache-Active
Front
CDN-RequestId
X-Httpd
X-Mode
X-Use-Mantle
X-Use-Magma
OT-Force-Account-Verify
X-Upstream-Ht
X-Cache-Operation
X-Upstream-Ct
X-Xfnlog-Site
Filters
X-Endurance-Cache-Level
Meta-Geo
X-VC
X-Real-IP
X-Rn-Rsrv
Webserver
X-UPSTREAM-Address
X-Rewrite-Enabled
X-SaId
X-Proxy-Build
X-JoinUs
X-Tumblr-Pixel-2
Accept-Language
Selected-Fe
X-Timing-Wait
X-Tumblr-Pixel-3
X-Served-From
X-Worker
X-ProxyCache-Key
X-Origin
X-ProxyCache-Status
ServedBy
X-Director
X-Varnish-Cache-Hits
X-Soup
X-BYPASS-REASON
Azure-SiteName
Property-Id
Azure-RegionName
X-GeoCountry
Azure-InstanceId
Azure-Version
X-Server-W
X-Format
DB-Nickname
X-GeoCode
X-Handled-By
X-Cms-Context
X-SayCDN-TTL
X-Cache-Time
TWC-GeoIP-LatLong
X-S
X-Varnish-Age
Webcakes-App-Name
X-Say-Cacheable
X-No-Session
Webcakes-App-Version
X-Restarts
X-Adobe-Source
X-Redis-Cache
X-Origin-Hint
Webcakes-Region
X-VCT
TWC-Privacy
X-Lambda-Id
TWC-Device-Class
X-Labrador-Cache-Channel
TWC-Connection-Speed
Xserver
X-PHP-Host
TWC-GeoIP-Country
X-Say-TTL
TWC-Locale-Group
X-Logging-Id
Azure-SlotName
X-AWS-Id
X-Cache-Debug
Web-Mar-Node
Mn-Server-Ip
X-Detected-As
X-Cache-Server
X-Fetched-On
X-IPLB-Instance
AMP-Access-Control-Allow-Source-Origin
X-Loop
X-Vercel-Cache
X-Tncms
X-IPLB-Request-ID
X-Vercel-Id
X-LJ-Flow-ID
Apigw-Requestid
X-Tb
X-Varnish-Beresp-Grace
X-VWS-Id
X-RCS-CacheZone
X-Skip-Cache
X-RM-Cache-TTL
X-Generation-Time
X-Ms-Version
X-Cache-Host
X-Ms-Request-Id
X-Reqid
X-Is-Desktop
X-Sql-Count
X-Container-Uri
X-Geo-Region
X-DynaTrace
X-Frame-Option
X-Sql-Duration-Ms
X-Git-Commit
X-Is-Mobile
X-Is-Supported-Browser
Section-Io-Id
X-Tcp-Rtt
X-Cluster
X-Is-Tablet
Node
Xet-Cookie
X-Browser-Name
X-AB
X-ServerID
X-Extlb
X-Locale
X-Forwarded-Host
X-Web-Node
X-R9-Blue-Green-Version
X-Proxied
X-Routing-Service
X-Zipkin-Id
Cross-Origin-Embedder-Policy
X-Site-Version
Cache-Tv-Group
X-Uri
X-COUNTRY
X-Platform-Router
X-Platform-Processor
X-Platform-Cluster
X-Provided-By
X-FB-TRIP-ID
X-Drupal-Cache-Contexts
X-Webstats-RespID
Priority
X-Drupal-Cache-Tags
Source
X-Vcache
Fastcgi-Useragent
X-MP-GENERATED-AT
Content-Secure-Policy
WP-Super-Cache
X-Origin-Date
CDN-CachedAt
CDN-RequestPullCode
CDN-RequestPullSuccess
CDN-Uid
CDN-RequestCountryCode
CDN-PullZone
CDN-Cache
CDN-EdgeStorageId
X-Vcl-Version
X-Storefront-Renderer-Rendered
Onion-Location
X-Alternate-Cache-Key
X-Shopify-Stage
WZWS-RAY
X-Xrds-Location
X-Content-Age
X-ShardId
X-Sorting-Hat-ShopId
X-Sorting-Hat-PodId
X-ShopId
S-Rt
X-Pass-Why
X-Sucuri-Cache
X-Generated-By
Locale
X-Urbn-Context-Path
X-Urbn-Site-Id
X-Cdn-Origin
X-TT-LOGID
X-Newrelic-Synthetics
X-Sucuri-ID
X-SRV
Sid
X-Cluster-Node
X-Ua
X-Varnish-Beresp-Ttl
X-Buckets
X-Proxy-Cache-Status
Cross-Origin-Embedder-Policy-Report-Only
X-Cache-Expired-At
X-Thinkindot-L3
Thinkindot-CacheControl
X-Scope-Id
X-Shield-Cache-Expires
X-Cache-Action
Thinkindot-Control
X-CMSURLCustom
TDXMobile
Cross-Origin-Window-Policy
Thinkindot-CacheControl-Type
X-LSADC-Cache
X-VCache
X-DataDome
Cache
Fastly-Drupal-HTML
X-Mg-Request-UUID
HostName
X-Via-Edge
X-Via-SSL
X-Aspnetmvc-Version
Atl-Traceid
Edge-Copy-Time
X-Via-CDN
X-S-Cookie
X-A-Dam
Gannett-Cam-Experience-Id
X-PAYTM-SRV-ID
X-D
X-Rojux
DCR-Decision-By
X-A-Dcw
Environment
X-Optimistic-Header
X-Cache-NE
X-A
Redirect-Candidate
X-BCube-Filmed-By
X-Bc-Bl
DCR-Processing-Time-Ms
Rendered-Blocks
X-A-Ccd
X-Conf
Type
T-Server
X-SRCache-Key
Sslversion
Lang
X-TIM-N
X-Application
Origin
X-Correlation-ID
X-Vtex-Remote-Cache
X-Vdms-Path
Ngx.Var.Host
X-Cache-Bucket
X-Aed
X-Bl-Debug
Ngx-Var-Key
X-Vdms-Version
Candidate-Md5Url
Meta-Geo-Continent
X-Destination
X-ScT
X-Ec-Fail
Surrogated-Key
X-Scheme
X-A-Dgt
X-A-Wwc
X-Ec-GeoHdr
X-Epic-Correlation-Id
X-External-Request-Id
Origin-Agent-Cluster
MD5-Digest
X-Developer
X-B-Cookie
X-Viewer-Country
CDCHOST
X-Datadome
X-GEO
X-TimeS
X-Request-URI
X-VG-TLSProxy
X-Varnish-Hostname
X-Access
X-Acquia-Purge-Cdn-Unconfigured
DSUID
Vix-Hermes-Req-Id
Fastly-GeoIP-CountryCode
V-Age
Host-ID
X-Varnish-Beresp-Status
X-Aicache-OS
X-B3-Trace-ID
Apple-News-Services-Handled
Apple-News-Services-Host
Apple-News-Services-Request-Url
Apple-News-Services-Parsed-Url
X-Varnishpool
X-Debug-Cache-Store
X-TH-Server
X-Node-Id
X-Nyt-Route
X-Op-Id-All
X-Mly-Id
X-Section
X-BBC-Edge-Cache-Status
X-Level-Front-Cache
X-Loc
Server-Host
Req-Svc-Chain
X-Origin-Time
X-Req
X-Request-Start
X-Request-Time
X-Rocket-Build-Number
X-Pubstack
X-Proxied-Request
X-SB
Req-ID
X-Platform
X-Pool
X-Sigma
X-Instance-Name
X-Core-Value
X-Debug-Cache-Fetch
X-Sigma-Backend
X-Ec-Custom-Error
X-Clientip
Release
X-Bip
L
X-WA-Info
X-We-Are-Hiring
Magicmarker
X-Dispatcher-Server
X-Thanos
X-Generated-On
Ssr
X-GeoIP-Country-Code
X-GeoIP-Region-Code
X-Gdpr
X-Origin-Response-Time
True-Client-Country-4JS
Tube-Get-Contents
Server-Hostname
X-SVT-ORM-VERSION
Server-Ext
Sever-Int
Tube-Got-Eval
Tube-Got-Results
Tube-Return
Uber-Trace-Id
X-Cache-TTL-Remaining
X-Server-IP
X-Men
X-Micro-Cache
X-Human
X-Gzip
X-GeoIP
X-GeoIP-City
X-NCache
X-Nginx-Cache-Key
X-RateLimit-Limit-Second
X-RateLimit-Remaining-Second
X-PERF
X-Org
X-SD-PageType
X-NMSegId
X-Geo-Header
X-From
X-Ad-Load-Variation
X-ApacheServer
X-Auto-Login
Wxu-Next-Region
Wxu-Next-Hostname
We-Hiring
Wxu-Next-Commit
X-Cache-Date
X-Cache-Id
X-Fastly-Cache
X-Forwarded-Site
X-Esi-Check
X-DPWN-IS-SECURE
X-Cache-Info
X-Device-Os
X-SVT-ORM-RULES
Country-Code
X-Up
X-V-Cache
Canary
Click-Count-Action-Start
X-TA-CDN-Provider
Gh-Request-Id
Fastly-SSL
Esi-Enabled
X-Var-Ttl
C-Via
X-WP-CF-Super-Cache-Cookies-Bypass
X-Zen-Fury
X-VServer
Cluster
X-VG-WebCache
Adler-Geo
X-Varnish-Director
Is-Eu
Click-Count-Error
Mail-Subject
Platform
X-UA-Device-Type
Pramga
Producers
On-Server
NM-Fastcgi-Cache
Machine
X-DC
User-Cache-Control
X-Service
X-Connection-Hash
Expiry
X-Core-Mission
X-Moov-Xdn-Version
Pics-Label
X-Moov-T
X-FC-Vary-Parameters
X-Cdn-Srv
X-Request-Host
X-Block-Status
X-ZONE
X-Contensis-Viewer-Groups
X-Edge-Server
X-Test
X-GoCache-CacheStatus
X-Cache-Aspx
Cache-Provider
X-Hash
W
Web-Mar-Region
X-Hnp-Log
X-Mvc-Supplant-OutputCached
A
X-Mvc-Supplant-Cachable
X-HS-Content-Campaign-Id
X-Gen-Mode
X-Varnish-Authentication
X-Fmm-Version
X-Proto
X-Irp-Debug
Cdn-Host
Cdn-Request-Time
Cf-Device-Type
X-Old-Content-Length
X-Policy
AKAMAI
X-Parent-Response-Time
X-Wikidot-Backend
X-Wikidot-Static-Cache
Content-Script-Type
Content-Style-Type
X-App-Name
X-Fastly-Backend
X-Via-Popn
X-Via-Poph
X-Eu-Site
X-Branch-Name
Fastly-Backend-Name
IsBot
L5d-Success-Class
NGX
X-Dc
X-Amz-Meta-Cb-Modifiedtime
RNT-Time
Ha-Gx-Prefs
HA-Ipaddr
RNT-Machine
X-Ah-Environment
X-HA-Backend
Cache-Key
X-Csrf-Jwt
X-CGP
Proxy-Firewall
X-CacheTTL
X-Via-Popv
X-Sn-Servicetimems
X-SIPLIST1
Datacenter
X-CF-Lambda-Fn
X-CF-Lambda-Version
Expect-Staple
X-Slack-Shared-Secret-Outcome
Cdn
N-Cache
X-Slack-Backend
X-Qloud-Router
X-ND-Cache
X-Owner
LB
Yak-Timeinfo
X-Region-Sid
X-LB-NoCache
X-Accel-Expires-Debug
X-Date
X-AK-Request-ID
Cdnsip
Cdncip
PFcat
X-Amz-Storage-Class
X-Tenant
X-VarnishDD-TTL
X-HN
X-Orig-Expires
X-Forwarded-Path
X-LB-ID
X-Cache-Type
Xc-Version
X-Shop-Environment
Locid
Cdn-Requestid
X-Ratelimit-Reset
X-Tt-Logid
X-Refresh
X-NGINX-Cache
X-Servedbyhost
X-Tb-Optimization-Total-Bytes-Saved
X-Gamma-Serve
X-Tx-Id
X-Varnish-Hits
X-Azure-Ref-OriginShield
X-VHOST
Cmsid
X-Backend-Instance
Cmstype
NtCoent-Length
XM
X-DynaTrace-JS-Agent
Server-ID
RATING
X-Wa
X-Nc
SID
X-Srv
X-Cache-Backend
CPC-Cache
X-API-Version
X-Vmg-Version
X-Cdn-Diag
GeoIp-Country-Code
CPC-Age
X-CDN-Cache-Status
X-Fpc
CloudFront-Viewer-Country
X-Nananana
X-Origin-Expires
X-TX-ID
X-TIME
X-LAGOON
X-Lagoon
X-Via-Fastly
X-Akamai-Transformed
X-Api-Version
XkeyRZ
X-Proxy-CacheRZ
X-B3-Parentspanid
X-NewRelic-App-Data
CacheControlHeader
X-Hit
X-Zone
X-Variation
Uri
X-Nf-Request-Id
Resin-Trace
Cross-Origin-Opener-Policy-Report-Only
User-Agent
X-Client-Ip
X-UA
X-URL
X-CACHE-AGE
X-Presslabs-Stats
X-Amz-Meta-Opti
X-Fastly-Country-Code
X-Datacenter
MIME-Version
X-Info
True-Client-Ip
Tcn
X-LiteSpeed-Tag
VNS-Cache
VNS-Age
X-Location
Cache-Hits
X-Geo
X-Ig-Origin-Region
Lb
GeoIP-Latitude
X-HostName
X-Dynatrace-Js-Agent
X-LiteSpeed-Cache-Control
DataCenter
X-B3-Spanid
Fusion-Source
Fusion-Template-Id
Fusion-Component-Id
X-Vc
True-Client-IP
X-DataCenter
Cache-Name
Fusion-Content-Source
Fusion-Content-Id
Fusion-Deployment-Id
X-AIR-PT
X-NWS-UUID-VERIFY
Mime-Version
Hostname
Powered-By
X-Cloudmap
Origin-CC
X-Dispatcher-Number
X-HOST
Origin-EX
X-Jungle-Id
Fastly-Drupal-Html
X-CSRF-TOKEN
X-Segment-20210421
X-Cached-By
X-CS
Cf-Ipcountry
X-IAuth-Set-Uid
X-CUA
X-User
X-RID
X-Cdn-Forward
X-Webkit-Csp-Report-Only
X-Mid
Debug
Srv
X-Render-Time
Cl-Cache
X-MCACHE
X-Wormhole-Sdk
X-ECache
Load-Balancing
X-Varnish-Beresp-TTL
GeoIP-Country-Code
BehaviorPad-Version
X-Dispatch
Ohc-File-Size
X-Esi
X-Litespeed-Tag
X-Cs
X-Powered-By-VTEX-Cache
X-VTEX-Cache-Server
X-VTEX-Cache-Time
Edge-Cache
X-Oracle-DMS-ECID
X-Cdn-Cache-Status
X-Auth-Group-Type
X-FPC
Ohc-Cache-HIT
CDN
YJS-ID
Server-Id
X-WA
X-NC
X-ServedByHost
X-Cache-Enabled
X-Lb-Id
Location
Server-Info
X-NodeID
X-Ig-Push-State
X-Wp-Cf-Super-Cache
X-Lb-Nocache
CountryCode
My-App
X-Wp-Cf-Super-Cache-Cache-Control
X-Fastly-Backend-Reqs
X-VCL-Version
Wpo-Cache-Message
Wpo-Cache-Status
X-Litespeed-Cache-Control
Ms-Author-Via
X-Proxy-Cache-La3
Xkey-La3
X-Snapshot-Date
X-Cdn-Request-ID
X-Internal-Host
Odigeo-Trace-Id
Xkeylog
X-MiniProfiler-Ids
X-MSEdge-Features
X-Akamai-Pragma-Client-IP
CF-Ctrl
X-MSEdge-Flight
CF-Cached-On
X-Acquia-Purge-Tags
X-Acquia-Site
X-Acquia-Application-UUID
X-Acquia-Application-Trace
X-IN-APIGATEWAYSSL
Memory
Time
Section-Origin-Responded
X-Custom-Header
FSS-Cache
X-FL-QIT-DEBUG
Section-Io-Origin-Status
Srvid
Section-Io-Origin-Time-Seconds
X-IN-APIGATEWAY
X-FL-EDGE
Memcached
X-Nitro-Cache
X-Nitro-Cache-From
X-Nitro-Rev
X-App
OriginIP
Ngx
X-APP-VERSION
X-Shopid
X-Sorting-Hat-Podid
X-Shardid
X-Sorting-Hat-Shopid
X-Cache-Version
Geoip-Latitude
X-Te-Count
Akamai-Cache-Status
X-Pad
X-RequestId
X-Wp-Cf-Super-Cache-Cookies-Bypass
X-Via-PopN
X-Th-Server
X-Depends
X-PHP-Backend
X-Vgn-Hpd-Reason
X-Sucuri-Id
X-Fastly-Cache-Hits
X-Ha-Backend
X-Udemy-Cache-App-Namespace
X-Te-Duration-Ms
X-Dw-Trace-Id
X-Via-PopV
X-Service-Response-Time
X-Via-PopH
X-Web-Server
X-Serial
X-Check-Cacheable
X-Cache-FS-Status
X-Lsadc-Cache
X-Mg-Cache
X-Http-Count
X-Http-Duration-Ms
Sm-Log-Id